pjfanning opened a new pull request, #1291: URL: https://github.com/apache/pekko-http/pull/1291
cherry pick 44b01c355969a4e0a3083a1ca46522d234a92b74 #1267 Motivation: When a modelled header value fails to parse, `ModeledHeaderValueParser` calls `onIllegalHeader` - which by default only logs - and degrades the header to a `RawHeader`. For `Transfer-Encoding` that is unsafe: the degraded header never reaches the `case h: Transfer-Encoding` arm in `parseHeaderLines`, so `isChunked` stays false and, with a Content-Length also present, the message is framed by Content-Length. An upstream that does parse the value - stripping quotes, tolerating trailing junk - frames the same message as chunked. The two disagree about where the message ends, which is a request smuggling primitive. Pekko HTTP already rejects the clear cases: `chunked` together with a Content-Length, an unsupported coding, and multiple entries. Only the unparseable value was silently tolerated. Modification: Fail the message when a `Transfer-Encoding` header arrives as a `RawHeader`. That can only happen when the modelled parse failed: `transfer-encoding` is in `alwaysParsedHeaders`, so it is modelled even when `modeled-header-parsing` is off, and a well-formed value always reaches the modelled arm. Result: A message whose Transfer-Encoding cannot be understood is rejected rather than framed by a different rule than the sender used. Tests: - sbt "http-core/testOnly org.apache.pekko.http.impl.engine.parsing.*" - pass (246 tests); a new test sends `Transfer-Encoding: "chunked"` alongside a Content-Length and expects a 400. Verified it fails without the change, where the message is accepted and framed by Content-Length. - sbt http-core/mimaReportBinaryIssues - pass References: None - rejects a message whose Transfer-Encoding value cannot be parsed -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
